CSIDB logo
Incident

Pitești children's hospital

Incident posture

Attack window
Feb 2024
Location
Romania
Status
Resolved
CIA posture
Available to members
Updated
2026-09-09 15:49

Linked entities

Victim
Pitești children's hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2024
Discovered
Feb 2024
Disclosed
Undetermined
Resolved
Feb 2024

Summary

Hospitals across Romania were hit by a ransomware attack that exploited the Hippocrates medical software, with the Pitești children's hospital among the first to notice system errors. The infection spread through BackMyData, encrypting files and demanding bitcoin payment. In response, the national cyber‑security centre ordered more than 100 facilities to disconnect from the internet, forcing staff to revert to paper records and offline workarounds while IT teams worked with the software provider to isolate the threat. Investigators found 26 hospitals compromised, and after several days most were restored from backups, resuming near‑normal operations without reported fatalities or serious patient harm.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The cyber‑attack began when criminals breached the Bucharest‑based software firm RSC and inserted a ransomware strain called BackMyData into the widely used Hippocrates medical system. On the Sunday following the breach, staff at Pitești children's hospital, located north‑west of Bucharest, were the first to notice errors in the Hippocrates interface. By dawn on Monday, numerous other hospitals across Romania reported that the Hippocrates system was down or behaving erratically. In response, the national cyber‑security centre issued an order to more than 100 hospitals to disconnect from the internet immediately. This disconnection forced medical staff to abandon all connected devices, emails and web browsers.

Without access to digital records, clinicians at Pitești children's hospital and elsewhere switched to pen and paper, improvising workarounds to continue patient care. Hospital doctors created offline methods to register every patient, requested laboratory results on paper, and used Excel and other offline tools to track treatments and supplies. The sudden shift to analogue processes increased the workload in waiting rooms, and some frustrated patients directed anger at staff, questioning what would happen if it were their relatives. Despite the disruption, the article notes that there were no reported deaths or serious harm to patients during the outage. Recording all new information on paper later required weeks of data entry, and some data captured during the period was lost forever.

IT teams worked closely with the maker of Hippocrates to determine the scope of the infection and to expel the attackers, confirming that 26 hospitals had been infected with the BackMyData ransomware. The next day, hospitals that had not been compromised were brought back online with additional protective measures in place. Within five days, the majority of the affected hospitals resumed operations close to normal, with internet connectivity restored and systems verified. Police have not commented on their investigation into the identity of the attackers, though the article notes that a ransomware gang linked to BackMyData had its website taken down the previous year and four Russians were arrested outside Russia. The national cyber‑security centre highlighted that the rapid disconnection and coordinated response bought time to assess the attack and restore services.

Sources

Sources available to members: 1 source.

CSIDB